US5594227A

System and method for protecting unauthorized access to data contents

Claim Score by NHIP

Read claim 14, the broadest

Abstract

A smart card protection system is provided for protecting against unauthorized access of data contents on a smart card through human or electronic-machine tampering. The smart card protection system includes a smart card having an authorized password stored thereon for associated data and a smart card terminal to supply an entered password for accessing the data on the smart card. The smart card includes a comparator to compare the entered password to the stored password, and two counters: a fail counter and a delay counter. The fail counter keeps a fail count indicative of the number of times that the entered password fails to match the stored password. The fail counter is incremented when the entered password fails to match the stored password and decremented when the entered password successfully matches the stored password. The delay counter maintains a delay count that is incremented each time the comparator compares the entered password to the stored password regardless of a match. In the event that the fail count is not equal to its starting value of zero, the smart card denies access to the data contents. Access is denied even though a match might occur after initial misses because the fail count is not zero. Further, when access is denied, a delay period is imposed before comparing the next entered password received from the smart card terminal. The delay period increases each time based upon a function of the delay count.

Term

Term ended

Expired 28 March 2015, 11.5 years ago.

  1. Priority and filed
  2. Granted
  3. Expired
  4. Today

28 claims: 5 independent, 23 dependent

  1. 1
    An integrated circuit (IC) card protection device for protecting against unauthorized access of data contents on an IC card, the IC card protection device comprising:a memory to store a password;a data input to receive an entered password;a comparator to compare the entered password to the stored password;a fail counter, operatively coupled to the comparator, to keep a fail count that is incremented away from a reference value when the entered password fails to match the stored password and decremented back toward the reference value when the entered password successfully matches the stored password;a delay generator to produce a delay period when the entered password fails to match the stored password;the IC card denying access to the data contents when the fail counter is not equal to the reference value and delaying for a delay period before undertaking comparison of the next entered password;andthe IC card permitting access to the data contents when the fail counter is at the reference value and the entered and stored passwords match.
  2. 8
    An integrated circuit (IC) card protection system for protecting against unauthorized access of data contents on IC card through human or electronic-machine tampering, the IC card protection system comprising:an IC card;an IC card terminal to supply an entered password for accessing the IC card;the IC card comprising:a memory to store a password;a data input to receive the entered password from the IC card terminal;a comparator to compare the entered password to the stored password;a fail counter, operatively coupled to the comparator, to keep a fail count indicative of a number of times that the entered password fails to match the stored password, the fail counter being incremented away from a reference value when the entered password fails to match the stored password and decremented back toward the reference value when the entered password successfully matches the stored password;a delay counter, operatively coupled to the comparator, to maintain a delay count indicative of a number of times that the entered password is compared to the stored password, the delay counter being incremented each time the comparator compares the entered password to the stored password;andin the event that the fail count kept in the fail counter does not equal the reference value, the IC card denying access to the data contents and delaying for a delay period that is a function of the delay count before comparing a next entered password received from the IC card terminal.
  3. 14
    Broadest claimClaim Score 54, average(NHIP)A method for protecting against unauthorized access of data contents on an integrated circuit (IC) card, the method comprising the following steps:(a) storing an authorized password on the IC card;(b) initializing a fail count to a reference value;(c) receiving an entered password;(d) comparing the entered password to the authorized password;(e) in the event that the entered password fails to match the authorized password, denying access to the data contents on the IC card and incrementing the fail count;(f) in the event that the entered password successfully matches the authorized password but the fail count does not equal the reference value, denying access to the data contents on the IC card and decrementing the fail count;and(g) delaying for a delay period when access to the data contents is denied before undertaking one of steps (c) or (d) for a next entered password.
  4. 20
    In a data protection system the compares an entered password to an authorized password for purposes of permitting or denying access to data content, a protection component comprises:a fail counter to keep a fail count indicative of a number of times that the entered password fails to match the authorized password, the fail counter being initialized to a reference value;a delay counter to maintain a delay count indicative of a number of times that the entered password is compared to the authorized password;in the event that the entered password fails to match the authorized password, the fail counter incrementing the fail count away from the reference value and the delay counter incrementing the delay count;in the event that the entered password successfully matches the authorized password, the fail counter decrementing the fail count back toward the reference value and the delay counter incrementing the delay count;andwhereby access to the data content is denied when the fail count kept in the fail counter does not equal the reference value and a delay period that is a function of the delay count is imposed before a subsequent comparison of the entered and authorized passwords is undertaken.
  5. 24
    In a system that compares an entered password to an authorized password for purposes of permitting or denying access to data content, a method for protecting against unauthorized access to data contents comprising the following steps:(a) initializing the fail count to a reference value;(b) receiving an entered password;(c) comparing the entered password to an authorized password;(d) in the event that the entered password fails to match the authorized password, (1) denying access to the data contents, (2) incrementing a fail count, (3) delaying for a delay period that is a function of a delay count before undertaking one of steps (b) or (c) for a next entered password, and (4) incrementing the delay count;(e) in the event that the entered password successfully matches the authorized password and the fail count does not equal the reference value, (1) denying access to the data contents, (2) decrementing the fail count, (3) delaying for the delay period before undertaking one of steps (b) or (c) for a next entered password, and (4) incrementing the delay count;and(f) in the event that the entered password successfully matches the authorized password and the fail count is equal to the reference value, permitting access to the data contents.